generated: '2026-08-26' method: probed source: >- Live DNS/TLS/HTTP probes of the hosts NiKang Therapeutics controls, run 2026-08-26 by 0-working/probe-domain-security.py and then trimmed by hand. The tool also probed developer.wordpress.org and oembed.com because those are the humanURL hosts on the API entries; both were removed, because they are upstream specification/documentation hosts that NiKang does not operate and their posture must not be credited to NiKang. note: >- www.nikangtx.com terminates TLS at Cloudflare in front of a WP Engine origin. HSTS is NOT set on either the site HTML or the /wp-json responses, and no CAA record is published for nikangtx.com, so any CA may issue for the zone. Email authentication is the strongest part of the posture: SPF is published and DMARC is at policy `reject`. DNSSEC is not enabled on the zone. hosts: - host: www.nikangtx.com https: true tls_version: TLSv1.3 cert_expires: 'Nov 8 04:56:30 2026 GMT' hsts: false edge: >- Cloudflare (server header `cloudflare`, cf-ray present) in front of a WP Engine origin (x-powered-by header `WP Engine`). notes: >- /wp-json responses carry `x-content-type-options: nosniff` and `x-robots-tag: noindex`. No Strict-Transport-Security, no Content-Security-Policy and no Referrer-Policy header was returned on either the HTML root or the JSON API. domains: - domain: nikangtx.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: reject